Singapore Image Gallery多个远程漏洞

漏洞信息详情

Singapore Image Gallery多个远程漏洞

漏洞简介

Image Gallery Web Application 0.9.10版本的admin.class.php中addImage类函数不能正确的检查文件名,远程攻击者利用该漏洞上传且执行任意文件。

漏洞公告

The vendor has released singapore 0.9.11 beta to address these issues:
singapore singapore 0.9 a beta

singapore singapore 0.9 beta

singapore singapore 0.9.1 beta

singapore singapore 0.9.10

singapore singapore 0.9.10 beta

singapore singapore 0.9.2 beta

singapore singapore 0.9.3 beta

singapore singapore 0.9.4 beta

singapore singapore 0.9.5 beta

singapore singapore 0.9.6 beta

singapore singapore 0.9.7 beta

singapore singapore 0.9.8 beta

singapore singapore 0.9.9 a beta

singapore singapore 0.9.9 b beta

参考网址

来源: BID
名称: 11990
链接:http://www.securityfocus.com/bid/11990

来源: XF
名称: singapore-adminclass-file-upload(18531)
链接:http://xforce.iss.net/xforce/xfdb/18531

来源: BUGTRAQ
名称: 20041216 [SIG^2 G-TEC] singapore Image Gallery Web Application v0.9.10 Multiple Vulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=110323479715051&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享